Microsoft Certified: Azure Administrator AssociateImplement and manage hybrid identitiesMedium

A company is implementing Azure AD Connect and plans to use Pass-through Authentication (PTA). They need to deploy PTA agents in a highly available configuration to ensure continuous authentication services. Which measure should they take to meet this requirement?

  1. AInstall the PTA agent on a domain controller in each forest.
  2. BConfigure a load balancer in front of the PTA agents.
  3. CInstall the PTA agent on the same server as Azure AD Connect.
  4. DDeploy multiple PTA agents on separate servers.
Show answer & explanation

Correct answer: D. Deploy multiple PTA agents on separate servers.

For high availability with Pass-through Authentication, you must deploy multiple PTA agents on separate servers. Azure AD automatically distributes authentication requests among the available agents.

Why the other options are wrong

  • A. While PTA agents can be installed on domain controllers, installing them on separate domain controllers in each forest doesn't inherently ensure high availability for the overall PTA service across all forests if only one agent is used per forest.
  • B. Azure AD automatically handles load balancing for PTA agents; an external load balancer is not required or supported for this purpose.
  • C. Installing on the same server as Azure AD Connect does not provide high availability; if that server fails, authentication services will be interrupted.

PTA High Availability

Ensuring continuous operation of Azure AD Pass-through Authentication by deploying redundant authentication agents to handle authentication requests even if one agent fails.

  • Achieved by deploying multiple PTA agents on separate servers.
  • Azure AD automatically distributes authentication requests across active agents.
  • Requires no additional load balancing infrastructure.

Memory trick: To keep the 'pass-through' flowing, have many 'agents' ready.

More Implement and manage hybrid identities questions